Impact
The ESPHome Device Builder Dashboard previously used the environment variables $USERNAME and $PASSWORD for authentication. When the internal names were changed to $ESPHOME_USERNAME and $ESPHOME_PASSWORD, the implementation no longer accepted the old names with no fallback, causing the dashboard to start without any authentication after an upgrade. This flaw allows any user who can reach the dashboard port to gain full access, potentially exposing configuration data, controlling connected devices, and facilitating further network compromise. The vulnerability falls under CWE-306, reflecting an improper handling of authentication credentials.
Affected Systems
All deployments of the ESPHome Device Builder dashboard running a version older than 1.0.12, as well as legacy esphome dashboards that still rely on $USERNAME and $PASSWORD, are vulnerable. The esphome container provides the patch in the 2026.6.2 release by upgrading the pinned device-builder to 1.0.12. Any instance that has not applied this update or that has not migrated the environment variables is at risk.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is classified as critical. The EPSS score is < 1%, indicating a very low current exploitation probability, though the CVSS score indicates a severe impact. The vulnerability is not listed in the CISA KEV catalog. Attackers only need network connectivity to the dashboard port and the presence of an upgraded but misconfigured instance that relied on legacy $USERNAME/$PASSWORD variables. Because the dashboard remains open unless operators rename the environment variables or apply the patch, an unauthenticated attack can easily read or modify device configurations, inject commands, or otherwise control devices.
OpenCVE Enrichment
Github GHSA